Joined
·
79 Posts
i've been trying to kill this virus for a few days with combofix and HJT logs with no success...


symptoms:
1. C:\Windows\Update.dll
basically adds a bunch of .cn (Chinese) entries to "HOSTS" file
appears as rundll32.exe in task manager
2. random .dll's in C:\Windows\system32
such as "950D1600.dll"
3. System.exe file in system32
in properties
description: HB Inject Application Version 1.2.1.1007
copyright: Copyright ? 2008, HB Software
original file name: HBInject.exe
4. C:\Program Files\Messenger\msgmr.dll
appears as rundll32.exe in task manager
5. changing of startup entries in msconfig, specifically to include the System.exe, msgmr.dll, and Update.dll
6. C:\Documents and Settings\(user name)\Local Settings\temp\wmsetup.dll
perflib_perfdata(random three #/letter sequence).dat is also in that folder
7. none of these files can be deleted unless in safe mode or during restart
for a few days, I simply killed the rundll32.exe processes and manually changed the HOSTS file
then i deleted the msgmr.dll and update.dll files, but they reappeared
two days ago, I checked my HJT log, and found a bunch of weird registry things, so I opened regedit and deleted every one of them
one of them had to do w/ "thunderadvise.dll", which i promptly deleted
the HJT log was clean, but only temporarily
I ran combofix several times and it deleted everything i've mentioned above but...
the same symptoms keep appearing
DDS log
DDS (Version 1.0) - NTFSx86
Run by demo at 15:22:40.89 on Thu 11/27/2008
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.628 [GMT -8:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\demo\Desktop\New Folder (2)\opera\op.com
C:\Documents and Settings\demo\Desktop\dds.scr
============== Psuedo HJT Report ===============
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
mRun: [HBService32] System.exe
dRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll
AppInit_DLLs: HBmhly.dll
SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - c:\program files\messenger\msgmr.dll
SEH: {950D1600-DE4A-448D-93B4-7BAE5A7A8052} - 950D1600.dll
SEH: {DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA} - DFB3DAC5.dll
SEH: {DA63E650-537C-4042-87BB-9D19D844680B} - DA63E650.dll
============= SERVICES / DRIVERS ===============
R3 d812a079;d812a079;\??\c:\windows\system32\d812a079.sys [2008-11-27 5504]
S0 HBKernel32;HBKernel32 Driver;c:\windows\system32\drivers\HBKernel32.sys [2008-11-27 14699]
S1 vcdrom;Virtual CD-ROM Device Driver;\??\C:\VCdRom.sys []
S3 6457aed;6457aed;\??\c:\windows\system32\6457aed.sys [2008-11-27 5504]
S3 b160485;b160485;\??\c:\windows\system32\b160485.sys [2008-11-18 5504]
S3 d435fd4;d435fd4;\??\c:\windows\system32\d435fd4.sys [2008-11-16 5504]
S3 de8296f;de8296f;\??\c:\windows\system32\de8296f.sys [2008-11-12 5504]
S3 f35ee9e;f35ee9e;\??\c:\windows\system32\f35ee9e.sys [2008-11-13 5504]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\NSNDIS5.SYS [2004-3-23 17280]
=============== Created Last 30 ================
2008-11-27 15:05 250 a------- c:\windows\gmer.ini
2008-11-27 14:58 19,968 a------- c:\windows\system32\HBmhly.dll
2008-11-27 14:58 7,680 a------- c:\windows\system32\System.exe
2008-11-27 14:58 14,699 a------- c:\windows\system32\drivers\HBKernel32.sys
2008-11-27 14:58 13,080 a--sh--- c:\windows\system32\DA63E650.dll
2008-11-27 14:58 252 a--sh--- c:\windows\system32\DA63E650.cfg
2008-11-27 14:58 5,504 a------- c:\windows\system32\6457aed.sys
2008-11-27 14:58 14,076 a--sh--- c:\windows\system32\DFB3DAC5.dll
2008-11-27 14:58 216,451 a--sh--- c:\windows\system32\950D1600.dll
2008-11-27 14:58 344 a--sh--- c:\windows\system32\950D1600.cfg
2008-11-27 14:58 5,504 a------- c:\windows\system32\d812a079.sys
2008-11-27 14:58 237,568 a------- c:\windows\Update.dll
2008-11-27 14:31 <DIR> --d----- C:\ComboFix
2008-11-27 14:08 208 a--sh--- c:\windows\system32\A1A6BC2E.cfg
2008-11-27 13:45 1,298 a------- c:\windows\system32\tmp.reg
2008-11-27 13:44 289,144 a------- c:\windows\system32\VCCLSID.exe
2008-11-27 13:44 288,417 a------- c:\windows\system32\SrchSTS.exe
2008-11-27 13:44 87,552 a------- c:\windows\system32\VACFix.exe
2008-11-27 13:44 82,944 a------- c:\windows\system32\o4Patch.exe
2008-11-27 13:44 82,944 a------- c:\windows\system32\IEDFix.exe
2008-11-27 13:44 82,944 a------- c:\windows\system32\IEDFix.C.exe
2008-11-27 13:44 82,432 a------- c:\windows\system32\404Fix.exe
2008-11-27 13:44 53,248 a------- c:\windows\system32\Process.exe
2008-11-27 13:44 51,200 a------- c:\windows\system32\dumphive.exe
2008-11-27 13:44 25,600 a------- c:\windows\system32\WS2Fix.exe
2008-11-26 19:20 <DIR> --d----- c:\program files\Messenger
2008-11-26 19:05 161,792 a------- c:\windows\SWREG.exe
2008-11-26 19:05 98,816 a------- c:\windows\sed.exe
2008-11-26 13:31 <DIR> --d----- c:\program files\common files\Macrovision Shared
2008-11-26 12:37 54,156 a---h--- c:\windows\QTFont.qfn
2008-11-26 12:37 1,409 a------- c:\windows\QTFont.for
2008-11-25 14:06 236 a--sh--- c:\windows\system32\FFAE967F.cfg
2008-11-25 14:06 432 a--sh--- c:\windows\system32\D9C002DD.cfg
2008-11-25 13:36 <DIR> --d----- c:\docume~1\demo\applic~1\Download Manager
2008-11-21 17:18 208 a--sh--- c:\windows\system32\DFB3DAC5.cfg
2008-11-20 16:11 145 a------- c:\windows\Eudcedit.ini
2008-11-18 14:28 244 a--sh--- c:\windows\system32\E1D19FCC.cfg
2008-11-18 14:28 5,504 a------- c:\windows\system32\b160485.sys
2008-11-16 18:39 5,504 a------- c:\windows\system32\d435fd4.sys
2008-11-15 14:10 <DIR> --d----- c:\docume~1\demo\applic~1\Audacity
2008-11-15 13:40 <DIR> --d----- c:\docume~1\demo\applic~1\FrostWire
2008-11-15 13:25 220 a--sh--- c:\windows\system32\B8E83D3C.cfg
2008-11-15 13:23 73,728 a------- c:\windows\system32\javacpl.cpl
2008-11-13 18:08 5,504 a------- c:\windows\system32\f35ee9e.sys
2008-11-12 20:28 453,632 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 20:28 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll
2008-11-12 16:47 5,504 a------- c:\windows\system32\de8296f.sys
2008-11-05 18:00 204 a--sh--- c:\windows\system32\C8FFD223.cfg
2008-11-05 17:57 272 a--sh--- c:\windows\system32\F2CBFAC4.cfg
2008-11-03 15:30 <DIR> --d----- c:\windows\pss
2008-11-03 15:20 204 a--sh--- c:\windows\system32\E5D39975.cfg
2008-11-03 15:19 436 a--sh--- c:\windows\system32\F8E07BB2.cfg
2008-11-02 16:50 <DIR> --d-h--- c:\windows\[email protected]
2008-11-01 13:30 <DIR> --d----- C:\New Folder (x)
2008-11-01 13:10 <DIR> --d----- c:\docume~1\demo\applic~1\uTorrent
2008-10-29 14:31 <DIR> --d----- c:\windows\Cache
==================== Find3M ====================
2008-11-14 19:12 <DIR> --d----- c:\docume~1\demo\applic~1\vlc
2008-11-06 14:02 <DIR> --d----- c:\program files\MUSICMATCH
2008-11-06 13:59 <DIR> --d----- c:\program files\lynx
2008-11-06 13:57 <DIR> --d----- c:\docume~1\demo\applic~1\Dev-Cpp
2008-11-06 13:56 <DIR> --d----- c:\program files\Apoint
2008-11-02 17:00 27,136 a------- c:\windows\apppatch\AcLue.dll
2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll
2008-09-15 03:57 1,846,016 a------- c:\windows\system32\win32k.sys
2008-09-04 08:42 1,106,944 a------- c:\windows\system32\msxml3.dll
2008-08-29 20:06 1,350,664 a------- c:\windows\system32\msxml6.dll
2008-01-21 11:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2007-10-09 20:38 <DIR> --d----- c:\docume~1\demo\applic~1\ScanSoft
2007-09-10 21:10 <DIR> --d----- c:\docume~1\demo\applic~1\NJStar
2006-09-13 15:18 <DIR> --d----- c:\docume~1\demo\applic~1\Ethereal
2006-06-01 12:02 <DIR> --d----- c:\docume~1\demo\applic~1\WildPackets
2006-05-31 23:58 <DIR> --d----- c:\docume~1\demo\applic~1\PDFill
2006-05-31 19:51 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Symantec
2006-05-31 19:41 <DIR> --d----- c:\docume~1\demo\applic~1\MSNInstaller
2006-03-16 17:18 <DIR> --d----- c:\docume~1\demo\applic~1\Mikrotik
2006-03-11 16:07 <DIR> --d--r-- c:\docume~1\demo\applic~1\Brother
2006-03-11 15:23 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Brother
2006-01-18 16:51 <DIR> --d----- c:\docume~1\demo\applic~1\Symantec
2005-11-10 17:23 <DIR> --d----- c:\docume~1\demo\applic~1\Intel
2005-11-10 17:22 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Intel
2005-10-14 20:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Intuit
2005-10-14 20:43 <DIR> --d----- c:\docume~1\demo\applic~1\Jasc Software Inc
2004-08-10 10:13 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SBSI
2006-05-31 13:40 56 a--shr-- c:\windows\system32\2354A42A8E.sys
============= FINISH: 15:22:49.65 ===============
symptoms:
1. C:\Windows\Update.dll
basically adds a bunch of .cn (Chinese) entries to "HOSTS" file
appears as rundll32.exe in task manager
2. random .dll's in C:\Windows\system32
such as "950D1600.dll"
3. System.exe file in system32
in properties
description: HB Inject Application Version 1.2.1.1007
copyright: Copyright ? 2008, HB Software
original file name: HBInject.exe
4. C:\Program Files\Messenger\msgmr.dll
appears as rundll32.exe in task manager
5. changing of startup entries in msconfig, specifically to include the System.exe, msgmr.dll, and Update.dll
6. C:\Documents and Settings\(user name)\Local Settings\temp\wmsetup.dll
perflib_perfdata(random three #/letter sequence).dat is also in that folder
7. none of these files can be deleted unless in safe mode or during restart
for a few days, I simply killed the rundll32.exe processes and manually changed the HOSTS file
then i deleted the msgmr.dll and update.dll files, but they reappeared
two days ago, I checked my HJT log, and found a bunch of weird registry things, so I opened regedit and deleted every one of them
one of them had to do w/ "thunderadvise.dll", which i promptly deleted
the HJT log was clean, but only temporarily
I ran combofix several times and it deleted everything i've mentioned above but...
the same symptoms keep appearing
DDS log
DDS (Version 1.0) - NTFSx86
Run by demo at 15:22:40.89 on Thu 11/27/2008
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.628 [GMT -8:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\demo\Desktop\New Folder (2)\opera\op.com
C:\Documents and Settings\demo\Desktop\dds.scr
============== Psuedo HJT Report ===============
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
mRun: [HBService32] System.exe
dRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll
AppInit_DLLs: HBmhly.dll
SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - c:\program files\messenger\msgmr.dll
SEH: {950D1600-DE4A-448D-93B4-7BAE5A7A8052} - 950D1600.dll
SEH: {DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA} - DFB3DAC5.dll
SEH: {DA63E650-537C-4042-87BB-9D19D844680B} - DA63E650.dll
============= SERVICES / DRIVERS ===============
R3 d812a079;d812a079;\??\c:\windows\system32\d812a079.sys [2008-11-27 5504]
S0 HBKernel32;HBKernel32 Driver;c:\windows\system32\drivers\HBKernel32.sys [2008-11-27 14699]
S1 vcdrom;Virtual CD-ROM Device Driver;\??\C:\VCdRom.sys []
S3 6457aed;6457aed;\??\c:\windows\system32\6457aed.sys [2008-11-27 5504]
S3 b160485;b160485;\??\c:\windows\system32\b160485.sys [2008-11-18 5504]
S3 d435fd4;d435fd4;\??\c:\windows\system32\d435fd4.sys [2008-11-16 5504]
S3 de8296f;de8296f;\??\c:\windows\system32\de8296f.sys [2008-11-12 5504]
S3 f35ee9e;f35ee9e;\??\c:\windows\system32\f35ee9e.sys [2008-11-13 5504]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\NSNDIS5.SYS [2004-3-23 17280]
=============== Created Last 30 ================
2008-11-27 15:05 250 a------- c:\windows\gmer.ini
2008-11-27 14:58 19,968 a------- c:\windows\system32\HBmhly.dll
2008-11-27 14:58 7,680 a------- c:\windows\system32\System.exe
2008-11-27 14:58 14,699 a------- c:\windows\system32\drivers\HBKernel32.sys
2008-11-27 14:58 13,080 a--sh--- c:\windows\system32\DA63E650.dll
2008-11-27 14:58 252 a--sh--- c:\windows\system32\DA63E650.cfg
2008-11-27 14:58 5,504 a------- c:\windows\system32\6457aed.sys
2008-11-27 14:58 14,076 a--sh--- c:\windows\system32\DFB3DAC5.dll
2008-11-27 14:58 216,451 a--sh--- c:\windows\system32\950D1600.dll
2008-11-27 14:58 344 a--sh--- c:\windows\system32\950D1600.cfg
2008-11-27 14:58 5,504 a------- c:\windows\system32\d812a079.sys
2008-11-27 14:58 237,568 a------- c:\windows\Update.dll
2008-11-27 14:31 <DIR> --d----- C:\ComboFix
2008-11-27 14:08 208 a--sh--- c:\windows\system32\A1A6BC2E.cfg
2008-11-27 13:45 1,298 a------- c:\windows\system32\tmp.reg
2008-11-27 13:44 289,144 a------- c:\windows\system32\VCCLSID.exe
2008-11-27 13:44 288,417 a------- c:\windows\system32\SrchSTS.exe
2008-11-27 13:44 87,552 a------- c:\windows\system32\VACFix.exe
2008-11-27 13:44 82,944 a------- c:\windows\system32\o4Patch.exe
2008-11-27 13:44 82,944 a------- c:\windows\system32\IEDFix.exe
2008-11-27 13:44 82,944 a------- c:\windows\system32\IEDFix.C.exe
2008-11-27 13:44 82,432 a------- c:\windows\system32\404Fix.exe
2008-11-27 13:44 53,248 a------- c:\windows\system32\Process.exe
2008-11-27 13:44 51,200 a------- c:\windows\system32\dumphive.exe
2008-11-27 13:44 25,600 a------- c:\windows\system32\WS2Fix.exe
2008-11-26 19:20 <DIR> --d----- c:\program files\Messenger
2008-11-26 19:05 161,792 a------- c:\windows\SWREG.exe
2008-11-26 19:05 98,816 a------- c:\windows\sed.exe
2008-11-26 13:31 <DIR> --d----- c:\program files\common files\Macrovision Shared
2008-11-26 12:37 54,156 a---h--- c:\windows\QTFont.qfn
2008-11-26 12:37 1,409 a------- c:\windows\QTFont.for
2008-11-25 14:06 236 a--sh--- c:\windows\system32\FFAE967F.cfg
2008-11-25 14:06 432 a--sh--- c:\windows\system32\D9C002DD.cfg
2008-11-25 13:36 <DIR> --d----- c:\docume~1\demo\applic~1\Download Manager
2008-11-21 17:18 208 a--sh--- c:\windows\system32\DFB3DAC5.cfg
2008-11-20 16:11 145 a------- c:\windows\Eudcedit.ini
2008-11-18 14:28 244 a--sh--- c:\windows\system32\E1D19FCC.cfg
2008-11-18 14:28 5,504 a------- c:\windows\system32\b160485.sys
2008-11-16 18:39 5,504 a------- c:\windows\system32\d435fd4.sys
2008-11-15 14:10 <DIR> --d----- c:\docume~1\demo\applic~1\Audacity
2008-11-15 13:40 <DIR> --d----- c:\docume~1\demo\applic~1\FrostWire
2008-11-15 13:25 220 a--sh--- c:\windows\system32\B8E83D3C.cfg
2008-11-15 13:23 73,728 a------- c:\windows\system32\javacpl.cpl
2008-11-13 18:08 5,504 a------- c:\windows\system32\f35ee9e.sys
2008-11-12 20:28 453,632 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 20:28 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll
2008-11-12 16:47 5,504 a------- c:\windows\system32\de8296f.sys
2008-11-05 18:00 204 a--sh--- c:\windows\system32\C8FFD223.cfg
2008-11-05 17:57 272 a--sh--- c:\windows\system32\F2CBFAC4.cfg
2008-11-03 15:30 <DIR> --d----- c:\windows\pss
2008-11-03 15:20 204 a--sh--- c:\windows\system32\E5D39975.cfg
2008-11-03 15:19 436 a--sh--- c:\windows\system32\F8E07BB2.cfg
2008-11-02 16:50 <DIR> --d-h--- c:\windows\[email protected]
2008-11-01 13:30 <DIR> --d----- C:\New Folder (x)
2008-11-01 13:10 <DIR> --d----- c:\docume~1\demo\applic~1\uTorrent
2008-10-29 14:31 <DIR> --d----- c:\windows\Cache
==================== Find3M ====================
2008-11-14 19:12 <DIR> --d----- c:\docume~1\demo\applic~1\vlc
2008-11-06 14:02 <DIR> --d----- c:\program files\MUSICMATCH
2008-11-06 13:59 <DIR> --d----- c:\program files\lynx
2008-11-06 13:57 <DIR> --d----- c:\docume~1\demo\applic~1\Dev-Cpp
2008-11-06 13:56 <DIR> --d----- c:\program files\Apoint
2008-11-02 17:00 27,136 a------- c:\windows\apppatch\AcLue.dll
2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll
2008-09-15 03:57 1,846,016 a------- c:\windows\system32\win32k.sys
2008-09-04 08:42 1,106,944 a------- c:\windows\system32\msxml3.dll
2008-08-29 20:06 1,350,664 a------- c:\windows\system32\msxml6.dll
2008-01-21 11:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2007-10-09 20:38 <DIR> --d----- c:\docume~1\demo\applic~1\ScanSoft
2007-09-10 21:10 <DIR> --d----- c:\docume~1\demo\applic~1\NJStar
2006-09-13 15:18 <DIR> --d----- c:\docume~1\demo\applic~1\Ethereal
2006-06-01 12:02 <DIR> --d----- c:\docume~1\demo\applic~1\WildPackets
2006-05-31 23:58 <DIR> --d----- c:\docume~1\demo\applic~1\PDFill
2006-05-31 19:51 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Symantec
2006-05-31 19:41 <DIR> --d----- c:\docume~1\demo\applic~1\MSNInstaller
2006-03-16 17:18 <DIR> --d----- c:\docume~1\demo\applic~1\Mikrotik
2006-03-11 16:07 <DIR> --d--r-- c:\docume~1\demo\applic~1\Brother
2006-03-11 15:23 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Brother
2006-01-18 16:51 <DIR> --d----- c:\docume~1\demo\applic~1\Symantec
2005-11-10 17:23 <DIR> --d----- c:\docume~1\demo\applic~1\Intel
2005-11-10 17:22 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Intel
2005-10-14 20:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Intuit
2005-10-14 20:43 <DIR> --d----- c:\docume~1\demo\applic~1\Jasc Software Inc
2004-08-10 10:13 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SBSI
2006-05-31 13:40 56 a--shr-- c:\windows\system32\2354A42A8E.sys
============= FINISH: 15:22:49.65 ===============
Attachments
-
13.5 KB Views: 48
-
9 KB Views: 85